Frameworks

Every framework you carry. Curated, versioned, always current.

Stop interpreting regulations. Subscribe to them. When the release amends, GRAC surfaces the downstream impact before your auditor does.

ISORBINABHSOC 2DPDP
The GRAC Approach to Frameworks

Frameworks as living releases.

GRAC's content team maintains a curated library of authority artifacts. You consume them as living, versioned releases. ISO 27001:2022 isn't a PDF you map yourself — it's a structured release with sections, controls, classifications, Source Statements, normalized Practices and pre-defined obligations.

When a release amends, the Change Impact Engine surfaces which of your Practice Instances are affected. When you subscribe to a new framework, the Common Control Architecture shows how much of your existing operationalization already contributes.

Configure once. Comply many times. Adding a framework becomes incremental — not greenfield.

The Framework Template

Every framework page. Same structured answers.

Every framework in the library carries the same structured template, so every page you visit answers the same questions:

What the framework is authority, scope, jurisdiction

Who must comply applicability by industry, size, geography

How GRAC's library handles it curated Source Statements, statement classification, mapped Practices

Common Control Architecture overlaps which other frameworks share Practices with this one, so you see the compliance ROI on day one

Sample Practice Instances how the framework instantiates in typical operating contexts

Related Industry pages the sectors that most commonly carry this framework

Related Role pages which buyers (CCO, CISO, CAE, DPO, Quality) it lands with

Whitepapers & downloads deeper reading for analysts, architects and compliance leads

What You Get by Subscribing to a Framework

Six things, on every subscription.

1
The full curated release

every Source Statement extracted, positioned in source structure, classified

2
Mapped Practices

normalized templates that satisfy each Source Statement

3
Default operational parameters

execution frequency, evidence type, retention, criticality — inherited when you create Practice Instances

4
Version control

subscribe to the specific release you need (ISO 27001:2022 vs. ISO 27001:2013)

5
Living updates

when the authority amends, the Change Impact Engine surfaces every affected Practice Instance in your tenant

6
Common Control Architecture links

automatically inherit compliance contribution from Practices you've already operationalized for other frameworks

Author Your Own Internal Standards

Internal governance held to the same rigor.

Beyond subscribed authorities, you can author internal Source Statements alongside curated releases. Internal policies flow through the same pipeline as regulatory frameworks — same version control, same mapping to Practices, same operationalization and assurance. Internal governance held to the same rigor as external compliance.

Missing a Framework?

Our catalog grows every quarter.

Our catalog grows every quarter based on customer demand. If you carry a framework we haven't yet curated, tell us — we'll evaluate it for the roadmap.

READY TO SEE YOUR FRAMEWORKS IN GRAC?

Book a Demo.

Bring your top three frameworks. We'll show you the exact Practices that cover all three, the Common Control Architecture overlap, and the incremental effort to add the fourth.